CVE-2013-5331: Adobe Air
High severity, CVSS 9.3. EPSS: 72.5% chance of exploitation in the next 30 days.
Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before 3.9.0.1380, Adobe AIR SDK before 3.9.0.1380, and Adobe AIR SDK & Compiler before 3.9.0.1380 allow remote attackers to execute arbitrary code via crafted .swf content that leverages an unspecified "type confusion," as exploited in the wild in December 2013.
Affected products
- Adobe Air: before 3.9.0.1380 (fixed in 3.9.0.1380)
- Adobe Air SDK: before 3.9.0.1380 (fixed in 3.9.0.1380)
- Adobe Flash Player: from 11.0, before 11.7.700.257 (fixed in 11.7.700.257); from 11.8, before 11.8.800.175 (fixed in 11.8.800.175); from 11.9, before 11.9.900.700 (fixed in 11.9.900.700); from 11.0, before 11.2.202.332 (fixed in 11.2.202.332)
Published 2013-12-11. Last modified 2026-06-16.